마이크로칩 8월
This page was machine-translated and may differ from the original. View original

Gartner: “AI Inference Will Be the Main Cause of Privacy Breaches in 2029”

Google 우선 소스Published2026.08.03 11:04
AI-generated insights pose a greater threat than data breaches.
Gartner warned that the center of privacy breach threats is shifting from direct data leaks to AI-based inference. Analysis suggests that existing data protection systems have limitations in responding to sensitive information, such as health status or behavioral patterns, which can be inferred from anonymous and aggregated data alone.

Gartner announced on the 3rd that by 2029, most privacy breaches will result from inferences generated by AI about individuals, rather than the direct leakage of personally identifiable information (PII).

It was also projected that spending on data integrity protection would reach the same level as investment in confidentiality protection by 2028.

Bart Willemsen, a senior analyst at Gartner, stated, “The nature of privacy breaches is shifting from data leaks to insight leaks,” adding that “AI can recreate deep personal insights without being constrained by existing data controls.”

He added, “Inference attacks are even more dangerous because they are often not detected by existing detection systems,” explaining that “even if actual records are not leaked, sensitive information can be revealed through conclusions derived by AI.”

Gartner analyzed that as companies reduce the amount of personal data they retain due to regulatory and cost burdens, threat actors have gained the means to conduct AI-based inference-based attacks.

To address emerging inference-based privacy risks, Gartner recommends: applying privacy-by-design principles throughout the entire AI development and deployment process and regularly checking for algorithmic bias and unintended inference risks; adopting Privacy Enhancement Technologies (PET), such as differential privacy technologies, synthetic data, and privacy-preserving machine learning; limiting data collection to necessary scope and minimizing the attack surface through strict access controls and timely deletion; strengthening advanced monitoring and anomaly detection capabilities to identify inference-based threats; and AIIt recommended measures such as mandating a 'human in the loop' to verify loan results before processing sensitive data.
"In the future, privacy risks will depend more heavily on how AI interprets data than on how companies store data," said analyst Willemsen.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
명세환 기자
명세환 기자